Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2018-1273 | First vendor Publication | 2018-04-11 |
Vendor | Cve | Last vendor Modification | 2025-07-30 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1273 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2018-06-05 | Spring Data Commons remote code execution attempt RuleID : 46473 - Revision : 1 - Type : SERVER-OTHER |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2025-07-30 09:20:58 |
|
2025-07-15 01:06:45 |
|
2025-07-14 12:03:03 |
|
2025-06-26 01:06:34 |
|
2025-06-25 12:03:39 |
|
2025-03-15 00:21:53 |
|
2025-02-07 17:21:20 |
|
2025-01-28 00:21:06 |
|
2024-11-28 13:12:34 |
|
2024-08-02 12:53:24 |
|
2024-08-02 01:15:19 |
|
2024-07-23 09:27:30 |
|
2024-07-16 21:27:38 |
|
2024-02-02 01:51:42 |
|
2024-02-01 12:14:35 |
|
2023-09-05 12:49:36 |
|
2023-09-05 01:14:18 |
|
2023-09-02 12:49:12 |
|
2023-09-02 01:14:35 |
|
2023-08-12 12:52:55 |
|
2023-08-12 01:13:52 |
|
2023-08-11 12:47:08 |
|
2023-08-11 01:14:14 |
|
2023-08-06 12:45:42 |
|
2023-08-06 01:13:49 |
|
2023-08-04 12:45:56 |
|
2023-08-04 01:13:55 |
|
2023-07-14 12:45:58 |
|
2023-07-14 01:13:56 |
|
2023-03-29 01:47:31 |
|
2023-03-28 12:14:16 |
|
2022-10-11 12:41:13 |
|
2022-10-11 01:13:57 |
|
2022-07-26 00:30:02 |
|
2021-05-05 01:28:58 |
|
2021-05-04 13:09:22 |
|
2021-04-22 02:23:07 |
|
2020-05-23 02:10:52 |
|
2020-05-23 01:06:55 |
|
2019-10-10 05:20:20 |
|
2019-06-11 12:09:57 |
|
2019-03-29 00:19:10 |
|
2018-08-02 12:08:42 |
|
2018-08-02 01:07:00 |
|
2018-07-21 09:19:33 |
|
2018-05-24 00:19:26 |
|
2018-04-11 17:19:22 |
|